3 ms·
Indeed, replacing this with the list of top 100 passwords would be much more effective.
by fasterdom 7y ago
Indeed, replacing this with the list of top 100 passwords would be much more effective.
- alister 7y agoIt seems to do that too (comparing against a list of the top 500 passwords): https://github.com/bdmac/strong_password/blob/master/lib/strong_password/dictionary_adjuster.rb https://github.com/bdmac/strong_password/blob/master/lib/str...
- cyphar 7y agoOr, alternatively, switching to the haveibeenpwned API[1] or zxcvbn[2]. [1]: https://haveibeenpwned.com/API/v2 https://haveibeenpwned.com/API/v2 [2]: https://github.com/dropbox/zxcvbn https://github.com/dropbox/zxcvbn
- senorprogrammer 7y agoA long time ago I made a gem that does pretty much this: https://github.com/senorprogrammer/pil https://github.com/senorprogrammer/pil If you want this functionality, I recommend not using it as-is, given the security vuln GitHub is currently reporting. Rather, anyone has my permission to copy the code verbatim into your project. It's a pretty simple gem.